Scriptless Social Sharing
Scriptless Social Sharing has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Scriptless Social Sharing has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Scriptless Social Sharing is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-39529Scriptless Social Sharing <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Scriptless Social Sharing
Author
Robin Cornett
Scriptless Social Sharing is a wee plugin to add buttons to your posts/pages, to make it easier for your readers to share your content on social networks. The sharing links use the most basic methods provided by each network. There is no JavaScript, nothing fancy included in this plugin, so if you want fancy, this is not the plugin you’re looking for. It just builds a set of links. The sharing buttons are accessible–even if you choose the “Icons Only” button styles, the network names are still part of the buttons, just hidden in an accessible-ready manner. There is a small settings page, so you can make decisions about which content types should have sharing buttons and where, what buttons should be added, and whether or not to use the plugin’s styles. Beyond that, developers may like to make use of filters throughout the plugin. Banner/icon image credit: Ryan McGuire on Gratisography.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C